|
211661
|
9.8 |
CRITICAL
Network
|
squid-cache debian opensuse fedoraproject canonical
|
squid debian_linux leap fedora ubuntu_linux
|
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the att…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-11945
|
2024-11-21 13:58 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211662
|
7.5 |
HIGH
Network
|
ntop
|
ndpi
|
In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment m…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-11940
|
2024-11-21 13:58 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211663
|
9.8 |
CRITICAL
Network
|
ntop
|
ndpi
|
In nDPI through 3.2 Stable, the SSH protocol dissector has multiple KEXINIT integer overflows that result in a controlled remote heap overflow in concat_hash_string in ssh.c. Due to the granular natu…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2020-11939
|
2024-11-21 13:58 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211664
|
5.9 |
MEDIUM
Network
|
mailstore
|
mailstore_server
|
In MailStore Outlook Add-in (and Email Archive Outlook Add-in) through 12.1.2, the login process does not validate the validity of the certificate presented by the server.
|
CWE-295
Improper Certificate Validation
|
CVE-2020-11806
|
2024-11-21 13:58 |
2020-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211665
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2020-11649
|
2024-11-21 13:58 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211666
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-11506
|
2024-11-21 13:58 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211667
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and …
|
CWE-444
HTTP Request Smuggling
|
CVE-2020-11505
|
2024-11-21 13:58 |
2020-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211668
|
4.9 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity 2018.2 through 2019.2.1, a project administrator was able to see scrambled password parameters used in a project. The issue was resolved in 2019.2.2.
|
NVD-CWE-noinfo
|
CVE-2020-11938
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211669
|
9.8 |
CRITICAL
Network
|
jetbrains
|
space
|
In JetBrains Space through 2020-04-22, the password authentication implementation was insecure.
|
CWE-287
Improper Authentication
|
CVE-2020-11796
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211670
|
7.5 |
HIGH
Network
|
jetbrains
|
space
|
In JetBrains Space through 2020-04-22, the session timeout period was configured improperly.
|
CWE-613
Insufficient Session Expiration
|
CVE-2020-11795
|
2024-11-21 13:58 |
2020-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|